Splunk Search

How to insert rex expression "..." in a search from Splunk web framework?

Federica_92
Communicator

Someone know how insert a rex expression "..." in a search, using splunk framework?
search:

mvc.tokenSafe ("index=main  source=$sourcename$ File:read | rex "\[[^*](?.+)\]" | fields path | outputlookup read_rules.csv")

the " " gives me problems.
I have tried with ' ' "' "' or ." ". or "$ $"
I have no idea how to work around this.

0 Karma
1 Solution

sk314
Builder

have you tried escaping the inner quotes like so \" ?

View solution in original post

sk314
Builder

have you tried escaping the inner quotes like so \" ?

Federica_92
Communicator

Work, thank you!

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...